PCZONE 討論區 - 觀看單一文章 - 【警告】VML 漏洞會默默把你的資料傳送至遠方...
觀看單一文章
FYI
會員
【警告】VML Vulnerability is back...
Patch Tuesday, August Edition
Vulnerability in Vector Markup Language Could Allow Remote Code Execution (938127)
這篇真的不宜從置頂退下來, 都已經過了這麼久, M$ 仍然沒有完全解除VML Vulnerability 的紅色警報, 若非小弟是個好奇寶寶, 否則就會讓這則更新默默偷溜過去...

以下雖然是舊聞, 不過還是值得參考

Wednesday, September 20, 2006
VML Exploit - Internet Explorer
Use this link with IE to see an example of VML. If you have the dll registered, you'll see a clock. Once unregistered, you shouldn't see anything.

Microsoft's Outlook e-mail client is also potentially vulnerable for this exploit. But fortunately e-mail is treated as if from Restricted Sites by default, where Binary and Scripting Behaviors is disabled. By using a web-mail client and Internet Explorer you might still be vulnerable.
不過好家在的是, 經過以上實驗(IE only), 只要您曾經解除 regsvr32 /u "%CommonProgramFiles%\Microsoft Shared\VGX\vgx.dll", 則M$ 只更新, 並未將 vgx.dll 註冊回來, 所以您暫時不用擔心(不過小弟還是把以上指令又執行一遍), 但將來是永遠說不準的...

回覆